Threat Intelligence

Map your findings to MITRE ATT&CK techniques, track CISA KEV listings, monitor breach databases for your domains. Connects external threat data to your specific Sectora findings.

Three intel sources, one view

  • MITRE ATT&CK — every Sectora finding maps to one or more ATT&CK techniques. Filter your queue by technique (e.g. "show me all T1190 Exploit-Public-Facing-Application findings").
  • CISA KEV catalog — Known Exploited Vulnerabilities. Polled hourly. Any matching CVE in your SCA findings instantly gets re-prioritised to Critical.
  • Breach corpus monitoring — your domains + email patterns + employee emails (BYO list) are checked against the latest breach dumps. Match = leaked-credential signal with high confidence.

ATT&CK mapping in practice

TA0001 Initial Access
T1190 Exploit Public-Facing App
T1078 Valid Accounts
T1110 Brute Force
T1059 Command Execution
T1213 Info Repositories (leaked secrets)
T1552 Unsecured Credentials
T1556 Modify Auth Process

For each finding, the Threat Intel panel shows the mapped techniques + sub-techniques + a kill-chain visualization (where in the attack flow this sits). Useful when you're reporting risk to a security-mature board — they want techniques, not CVE IDs.

Trending techniques

The Trending dashboard shows ATT&CK techniques that have spiked across Sectora's customer base in the last 7/30/90 days — useful early warning. If T1190 spikes industry-wide, your public-facing apps just became higher-risk regardless of your specific findings.

KEV integration

CISA's KEV catalog is the authoritative list of CVEs with confirmed in-the-wild exploitation. Sectora polls hourly; any new addition that matches a finding in your SCA gets:

  • Severity re-rated to Critical (regardless of CVSS)
  • Risk score multiplier 1.5×
  • Alert fired immediately to your KEV-routing channel
  • Virtual-patch suggestion if Shield is enabled + a known mitigation pattern exists

Breach corpus monitoring

Sectora maintains an indexed view of public breach dumps (haveibeenpwned API + our own corpus). Your monitored domains + employee email patterns are checked daily; matches surface as Critical leaked-credential findings.

Set up at Settings → Threat Intel → Domains + Email patterns. The check uses k-anonymized hashing — your emails never leave your tenant in plaintext; only SHA-256 prefixes are sent to the corpus API.

Integrating with your SOC

For mature security teams running a SIEM, Sectora can stream the Threat Intel feed:

  • JSON over webhook — finding + mapped techniques + KEV context in real time
  • Splunk HEC ingest
  • STIX 2.1 feed (subscribe via Settings → Threat Intel → STIX endpoint)

What's next